Europe's critical infrastructure exposed to high-risk tech vendors, RUSI report finds

A new report from the Royal United Services Institute warns that Europe lacks a shared definition of what constitutes a high-risk ICT vendor, leaving telecoms and computer infrastructure in multiple countries vulnerable to potential hostile state interference.

The report, “High-Risk ICT Vendors and Critical Infrastructure: Comparing European Approaches”, examines the UK, Germany and Spain and finds that Chinese vendors including Huawei and ZTE remain deeply embedded across European networks. Chinese components accounted for 59% of Germany’s 5G radio access network, 32% in Spain and 20% in the UK as of 2024, according to a study cited in the research.

Among the specific examples the report identifies: cloud storage for judicial wiretap recordings in Spain is provided by Huawei. Under China’s National Intelligence Law and Counter-Espionage Law, these vendors can be required to cooperate with state security services.

The EU’s 5G security toolbox, published in January 2020, has so far been fully implemented by only 10 of 27 member states. The report concludes that the voluntary approach “has failed to produce a coherent European response.” National responses across the three countries studied have been shaped by different economic relationships with China, security perspectives and institutional capacities, producing incompatible frameworks.

The research makes several recommendations. For the EU, it calls for a shared vendor risk assessment framework combining stronger central oversight with clear criteria, evidence-based assessments, due process, transition periods and mechanisms for review. For the UK, it says legislation should be extended beyond telecoms and public procurement to cover the rest of critical national infrastructure, providing a statutory process for assessing high-risk vendors. It also recommends that the NCSC and DCMS adapt the Cyber Assessment Framework to address ownership-related risk from foreign control or influence.

On the question of how to treat US vendors relative to Chinese ones, the report advises against false equivalence, saying cross-European policy should focus on a framework capable of distinguishing the differing geopolitical and security risks posed by each. The EU’s proposed amendments to its Cybersecurity Act are described as the most far-reaching attempt so far to forge a common European approach, though closing the gap between legislative ambition and consistent implementation will require deeper institutional capacity and a willingness to treat technology procurement as a matter of strategic policy.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News